CVE-2026-79602 PUBLISHED

x86: improper handling of HVM emulation return codes

Assigner: XEN
Reserved: 25.08.2026 Published: 08.09.2026 Updated: 08.09.2026

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

Product Status

Vendor Xen
Product Xen
Versions Default: unknown
  • Version consult Xen advisory XSA-510 is unknown

Affected Configurations

Xen versions 4.6 and later are vulnerable. This is known to be the case with the fix for XSA-491, but it's possible the issue can also be triggered from other, non-analyzed paths.

Only x86 systems are vulnerable. Arm systems are not vulnerable.

Only HVM guests with a PCI device with IO BARs assigned can leverage the vulnerability.

Workarounds

There is no mitigation available.

Credits

  • This issue was discovered by Jiqian Chen of AMD and diagnosed as a security issue by Roger Pau Monné of AMD. finder

References

Impacts

  • Passing through a PCI device with at least one BAR in IO address space to unprivileged HVM guests can result in a Denial of Service (DoS) affecting the entire host.